# How to verify our claims

Each claim below comes with a command you can run. If a command disagrees with this page, the command is right and this page is wrong.

## Checkable now

- **heedeo.com really verifies Web Bot Auth signatures, against the operator's real key directory.** Claim to be ChatGPT with a made-up key:

  ```bash
  NOW=$(date +%s)
  curl https://heedeo.com/api/visitor \
    -H 'Signature-Agent: "https://chatgpt.com"' \
    -H "Signature-Input: sig1=(\"@authority\" \"signature-agent\");created=$NOW;expires=$((NOW+60));keyid=\"test\";alg=\"ed25519\";tag=\"web-bot-auth\"" \
    -H 'Signature: sig1=:AAAA:'
  ```

  Expect `signature.present` true, `signature.verified` false, `signature.reason` `"key not found in directory"`. Change `created` and `expires` to past times (for example 1700000000 and 1700000300) and the reason becomes `"expired"`.

- **A user agent string is not proof.** Claim to be ChatGPT with no signature:

  ```bash
  curl https://heedeo.com/api/visitor -A "ChatGPT-Agent"
  ```

  Expect `name` `"ChatGPT agent"` (detected) with `verified` false and `signature.reason` `"no signature headers"`.

- **A valid signature is not enough; the operator must be trusted.**

  ```bash
  curl "https://heedeo.com/api/decide?route=/signup&client=agent&signed=true&operator=agent.example-operator.com"
  ```

  Expect `verdict` `"challenge"` and a reason saying the operator "is not in trustedOperators, so the agent counts as unknown".

- **The policy engine is real and the demo policy is public.** Read the policy, then run requests through it:

  ```bash
  curl https://heedeo.com/api/policy
  curl "https://heedeo.com/api/decide?route=/signup&client=agent&signed=true&operator=chatgpt.com&principal=maya&count=2"    # allow, 200, line 8
  curl "https://heedeo.com/api/decide?route=/signup&client=agent&signed=true&operator=chatgpt.com&principal=maya&count=7"    # throttle, 429, retryAfter 3600, line 13
  curl "https://heedeo.com/api/decide?route=/signup&client=agent&signed=true&operator=chatgpt.com&principal=maya&count=11"   # block, 403, line 13
  curl "https://heedeo.com/api/decide?route=/signup&client=agent&signed=false"                                               # challenge, 401, line 10
  curl "https://heedeo.com/api/decide?route=/checkout&client=agent&signed=false"                                             # block, 403, line 15
  curl "https://heedeo.com/api/decide?route=/docs/../checkout&client=agent&signed=false"                                     # block, 403, line 15 (normalized)
  ```

  Each response names the policy line (`rule.line`, `rule.text`) that decided it. Check it against `source` from `/api/policy`.

- **The decision logic is per principal, and reasons don't leak who.** Given a principal and a count, `/api/decide` shows what the rules do with them. The `reason` says "This person is at 7/5 per day on /signup", and the principal only comes back in its own `principal` field, echoed from your input. What this does not show: identifying the principal and keeping the count happen in the package, inside your middleware. That part is shown on the call.

- **The booking API is what the docs say.** Without creating anything:

  ```bash
  curl -i https://heedeo.com/api/book                     # 405, Allow: POST
  curl -i -X POST https://heedeo.com/api/book -d 'nope'   # 400 with an "error" field
  ```

- **The site serves markdown to agents.**

  ```bash
  curl -sI https://heedeo.com/docs.md | grep -i content-type          # text/markdown
  curl -s -H "Accept: text/markdown" https://heedeo.com/ | head -3    # the page as markdown
  ```

- **The standards are real and public.** RFC 9421: https://www.rfc-editor.org/rfc/rfc9421. Cloudflare's signed agents list (ChatGPT agent, Goose, Browserbase, Anchor Browser): https://blog.cloudflare.com/signed-agents/

## Stated, not checkable by curl

- Backed by Entrepreneurs First (https://www.joinef.com). Ask us on the call.
- In your app, only decision metadata (route, verdict, agent, reason, rule line) reaches the dashboard, never request bodies. You can confirm this on your own network once you have the package.

## Known limits of the public demo

- Replay protection on heedeo.com is an in-memory cache per Workers isolate, not global. A replay that reaches another isolate is not caught. See https://heedeo.com/docs/security.md.
- `/api/decide` takes `signed` and `operator` as inputs; it does not check a signature itself. `/api/visitor` is the endpoint that verifies.

## What is not public yet

- **The package.** `@heedeo/next` is not on public npm. Access is provided at onboarding.
- **Customers.** There is no public customer list, and we don't publish logos or numbers.
- **Pricing.** There is no public price list.
- **Certifications.** We claim none.
- **Deployment details.** Where per-principal counters live, how replay state is shared, and whether outages fail open or closed are agreed during onboarding.
- **Policy keys beyond the ones in** https://heedeo.com/docs/rules.md: set up with you at onboarding.
- **A contact email.** The way to reach us is a call (https://cal.com/heedeo/30min) or `POST https://heedeo.com/api/book`.

---

Docs index: https://heedeo.com/docs.md. How to verify our claims: https://heedeo.com/trust.md. Book a call: https://cal.com/heedeo/30min

Updated: 2026-10-02
